The fix alone is not enough — every session had to be killed on Citrix NetScaler
For the buffer overflow in Citrix NetScaler ADC and NetScaler Gateway, CISA required agencies to apply mitigations and to kill all active and persistent sessions. Where no mitigation was available, use of the product was to stop.
Key facts
- CVE IDCVE-2023-4966
- Affected (vendor / product)Citrix NetScaler ADC and NetScaler Gateway
- CWECWE-119
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2023-11-08 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2023-4966 is a buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway.
- It allows sensitive information disclosure when configured as a gateway, such as a VPN virtual server, ICA proxy, CVPN or RDP proxy, or as an AAA virtual server.
- The required action is to put the mitigations on and, on top of that, to end every session, live or persistent.
- Where mitigations are unavailable, use of the product is to be discontinued.
- Listed 18 October 2023 with a due date of 8 November, a window of twenty-one days; of the 1,579 entries without an article this site holds as of 2026-09-05, 602 (38.1%) carry the phrase discontinue use.
1Closing the hole does not bring back what left through it
The previous article followed an entry where an account created by an attacker outlived the fix, so compromise had to be determined. The same shape appears here, but what outlives the fix is different. Here it is sessions.
2Two things at once
This flaw permits the disclosure of sensitive information. With what was disclosed, a path already established can remain usable after the flaw itself is closed. Killing the sessions is how that path is cut.
3An instruction joined by and
The pairing apply mitigations or else stop using it appears on 252 entries and is one of the standard forms. This entry is that form with kill all sessions added to it. The departure from the standard is what tells you about the flaw.
4Twenty-one days
Listed 18 October 2023, due 8 November: twenty-one days, the most common window of all. Against the four days in the previous article that looks generous, yet more work is asked for. The length of the window and the weight of the work are set independently.
The next article takes up an entry that set an order for returning a device to service: hunt, remediate, then update.
Why it matters
Closing a vulnerability does not retrieve what escaped through it. Where the flaw discloses sensitive information, an established path can be followed afterwards, so the instruction adds killing every session to applying the mitigation. That the standard pairing, mitigate or stop using it, gains one extra clause is itself a statement about the nature of the flaw.
FAQ
Why kill the sessions as well?
Which configurations are affected?
What if no mitigation is available?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).